Your AI agents’ access is the blind spot nobody is watching

Attacks that once took days now unfold in seconds. AI has given threat actors speed, scale, and a lower skill barrier, and India is feeling it: CERT-In flagged nearly 3.5 lakh malicious scanning and probing instances in financial services in H1 2026 alone, accounting for over 60% of 2025’s total. Security teams still running human-paced, manual processes cannot close that gap.

Mandy Andress, CISO at Elastic, is already running an Agentic SOC in production, where deterministic checks, forensics sub-agents, and an analysis agent hand off a finished investigation to a human analyst. Automated remediation is next on her list. The multi-agent design, she says, proved to be over five times cheaper per analysis than a single-agent design.

In this conversation with CISO Forum, she explains why analysts must challenge AI output rather than rubber-stamp it, why accountability matters when an agent gets it wrong, and why non-human identities, not guardrails, may be the most underweighted item on the CISO’s 2026 agenda.

Mandy Andress, CISO, Elastic

CISO Forum: Elastic notes AI-driven attacks can spread across a network in under a minute. What does that compression of attack timelines actually change about how a SOC needs to be staffed and structured compared to five years ago?

Mandy Andress: The speed of attacks has been increasing for several years, largely driven by the massive amounts of data organizations are now collecting and by cloud infrastructure generating far more log data and insights into what’s happening across the infrastructure. Bringing AI into the picture has sped that up even further. Analysis and actions that used to take hours to days now take seconds to minutes.

And so, from a SOC perspective, what that has changed is the focus on understanding how we apply AI technology to security on the defensive side as well. How do we take advantage of the analytics capabilities, the analysis capabilities, and the context and framing that AI can provide to allow us to respond at machine speed, the same speed that threat actors are working at?

The SOC is increasingly turning to autonomous triage. We tried this in the past with what became the SOAR tools, but that didn’t work because they were very deterministic. You had to define every step, and when your organization changed technologies or processes, you had to know that and update your SOAR playbooks. That was hard to do. It took a lot of staffing and a broad understanding of the organization that security teams sometimes didn’t have in their day-to-day work.

What AI brings to the SOC now is the ability to have much more detailed, granular, and real-time insight into what’s happening both across the organization and across the threat landscape, and to bring that entire context as inputs into a more AI-driven playbook. So, you’re able to stay current as the threat landscape and the organization change, and you’re able to do that in a much more real-time way than we’ve ever been able to before.

CISO Forum: India alone saw CERT-In flag nearly 3.5 lakh malicious scanning and probing instances in financial services in just H1 2026, more than 60% of 2025’s total volume. Is that acceleration coming from more attackers, better tools, or AI simply removing the skill barrier to entry?

Mandy Andress: The answer is a little bit of all of those. There are certainly more threat actors trying things because the skill requirements for some types of attacks have decreased. Experienced threat actors can also do more because of the speed and velocity AI enables.

Before, if they were trying an attack, they would try something and see if it worked. If it didn’t, they would have to figure out what to try next. Again, that could take hours, if not days, and sometimes longer between steps. Now, driven by AI, this happens in seconds or minutes, creating alerts, logs, and other information on the organization’s side that need to be analyzed and understood to determine whether any action is needed. So, I expect that trend to continue.

CISO Forum: Walk us through what an “Agentic SOC” looks like in practice at Elastic: where does AI’s authority to investigate and act end, and where does it hand off to a human analyst?

Mandy Andress: We’ve spent a lot of time this year testing our agentic capabilities and moving them into full production, running on Elastic Workflows and Elastic Agent Builder.

The way we operate today, and this is live in production, is that every alert that fires first goes through a deterministic check. This is about balancing SOC efficacy and cost. We know some things are high-confidence true positives. If one of those alerts fires, the only thing we want to do is investigate it so it gets handled and sent to an analyst immediately. Then there are alerts we know are false positives based on tuning, which we can remove.

We do that initial deterministic check, and then the things that we have questions about or need more information on go to the agent process. The first thing the agent does is review the alert to determine what information it needs and what type of analysis to perform.

We then have several sub-agents. These are distinct agents, which we call forensics agents, that focus on individual areas. So, if an alert comes in and indicates it is an endpoint alert originating from an AWS asset, we have an endpoint forensics agent that pulls the facts needed for endpoint analysis. We also have an AWS agent that pulls data from AWS.

Those are all very fact-based agents. We found that when we had them perform the analysis, they were very biased toward their particular focus, so we use them only to bring in the facts.

We then have the alert, the organizational context, and the forensics results, all of which are bundled together and passed to an analysis agent. That’s the agent that takes everything, puts it together, and performs the analysis a human analyst would.

But it’s analyzing much more data. It’s doing lookbacks and bringing in broader knowledge from threat intelligence, the broader community, and recommendations. All of that then gets packaged into a detailed analysis of what fired, the specifics of that alert in natural language, and the results of the forensic analysis.

There’s also a couple-sentence summary of the conclusion, the type of attack it was, and what happened, along with the agent’s recommendations for next steps. All of that gets presented to an analyst. At that point, the analyst takes over, and either asks more questions via a chat interface, performs additional analysis based on the focus, or completes actions.

What we’re just starting to do is test automated mitigation and automated remediation. We don’t have any of that in place today. The first part we’re testing will be on endpoints, such as isolating an endpoint that has a malware alert. We use Okta, so we’re also testing how to reset Okta sessions and quickly close out a user if we feel their account has been compromised. That’s the first automation step that we’re actively working on, and then we’ll continue to expand as we test and gain confidence, similar to how we moved to the triage process.

We did a lot of testing and parallel running. One interesting thing we found with the agent was that, in the beginning, we had one agent with many skills loaded into it. We found that was quite expensive from a token perspective. Breaking it up into multiple agents was much cheaper because you weren’t carrying that context over. A single analysis was over five times cheaper to complete using the multi-agent approach than the single-agent approach.

CISO Forum: With Attack Discovery investigating events and even drafting new detection rules, how do you prevent analysts from rubber-stamping AI output rather than genuinely exercising judgment?

Mandy Andress: When using AI, Attack Discovery scans your alert collection to help you understand which patterns might be emerging and what actions you might need to take. There’s still judgment involved in determining whether we take those actions in our environment from an attack-discovery perspective, and what additional information we need.

More broadly, the role of analysts these days is to challenge the AI output rather than take it as a rubber stamp, and that type of work needs to be built into their overall operational processes. So, ask questions, challenge, and push back. Then take that judgment-based analysis and apply whatever learnings they have to their alerts and their environment.

CISO Forum: As AI takes over triage and correlation, what does the CISO’s ideal SOC analyst look like in three years? What skills matter more, and which skills stop mattering?

Mandy Andress: For me, as a CISO, three years from now I would love to have automation of mitigation much more widely used than it is today. I do think that will be a slow process as we continue to adapt our overall environments, so that’s one thing I’d like to see.

I’d also like to see not just mitigation but remediation, and the ability to fix issues we identify through our ongoing analysis. Then I think the most interesting piece that I would love to have three years from now is the ability to see an attack in its early stages and make infrastructure configuration changes that can stop that attack.

For example, if a credential is exposed and analysis shows it’s doing things it shouldn’t, we could automatically close it, rotate it, create a new one, or take whatever appropriate action is needed. Then, if there’s additional movement, we could close off that asset and disrupt the process in real time, which is something we aren’t able to do today.

CISO Forum: AI agents are increasingly getting their own identities and permissions inside enterprise systems. What’s the biggest blind spot you see CISOs having today around governing non-human identities?

Mandy Andress: With non-human identities, the biggest thing for me right now is scale. We’re seeing an explosion in the number of identities within our organizations, and we already don’t do a good job of managing access.

More specifically, we don’t always understand exactly what access an agent has. We know what access it has been granted, but we don’t necessarily understand whether there are inherited permissions that the agent is getting that we don’t know about. We may not see the five layers of inheritance and realize that the second step gives the agent admin access.

So, from an agent perspective, we need to start truly with least privilege and not let agents assume permissions. We need to start with zero-trust and least-privilege principles, adding only the access the agent needs. That’s a significant shift, and one that many organizations aren’t necessarily ready for today, but they’ll need to focus on that area pretty quickly.

CISO Forum: If an AI agent takes an autonomous action that turns out to be wrong, say, an incorrect containment step, how should accountability be structured between the agent, the analyst who approved the workflow, and the CISO?

Mandy Andress: Many conversations are going on about this topic. For me, when it comes to using agents within an organization, if there’s a reasoning challenge, accountability goes back to the owner of the underlying reasoning model.

For actions, accountability lies with the process owner. So, if it’s a personal productivity agent, the individual is responsible for the agent’s actions. If it’s a production process with its own credentials and a team and a process owner, then that owner is responsible for what the agent does.

As CISO, I have overall accountability for the organization’s security, whether that involves humans, agents, or anything else that comes along. Having that clear accountability drives the need to ensure that we’re challenging the output, that we understand it before using it in business decisions, and that we aren’t simply doing something because AI told us to.

CISO Forum: An AI-native SOC needs a data foundation, including unstructured data. What does “good enough” data hygiene look like for a security team that wants to deploy AI agents responsibly, and where do most enterprises fall short today?

Mandy Andress: The biggest thing for a security team when it comes to data foundations is first understanding what data you need, then determining what data you actually have and the quality of the data available to you.

There are a couple of traps that organizations run into. They may not have access to the data they need. The data exists, but they aren’t bringing it into their analysis tools. In some cases, the organization isn’t capturing the data it needs, so that becomes a separate process. Sometimes, cost also plays a role. The cost of ingesting and storing data can limit what data is brought in, how much of it is brought in, or the level of detail available.

When it comes to the data foundation, start with the outcome. What do you want to understand? What do you want to be able to analyze and see? Then determine what data you need to achieve that.

Once you understand the outcome, you can also focus on data quality. There are some types of analysis where you can have data quality issues or errors, but there are other processes where the data has to be absolutely 100% correct. Knowing where to focus quality work within the data foundation is also very important.

CISO Forum: Attackers are also using AI for reconnaissance, phishing, and even adaptive malware. Does defending against an AI-augmented adversary require fundamentally different tooling, or is it still the same playbook, just run faster on both sides?

Mandy Andress: Right now, things are certainly moving faster on the attacker’s side, and from a defensive perspective, we cannot continue operating as we have been. We can’t successfully defend at that rate because most of our processes are human-driven and highly manual.

When threat actors operate at machine speed, and SOC analysts operate at human speed, there’s a significant imbalance, and that is what we need to close most quickly. Bringing Agentic SOC capabilities to machine-speed analyst processing is, and will continue to be, the first focus for many organizations.

Then, organizations will need to move towards a much more proactive defense posture. There will be fundamental shifts in how organizations think about risk as it relates to availability and downtime. It’s about really understanding the trade-off between downtime from an agent-driven attack and the time it takes for systems to go offline to apply a patch. I think some of those processes and risk appetite lines will shift over the next few years.

CISO Forum: Looking at 2026, what’s the one item you think is dangerously underweighted on most CISOs’ agendas right now: AI-powered attacks, agent governance, or something else entirely?

Mandy Andress: For me, I’ll go back to identity. I think we’re underestimating the importance of managing agents’ identities. There’s a lot of focus on the governance of agents and on guardrails, but at the end of the day, if your access isn’t right, then the governance and guardrails won’t be as effective as they could or should be.

Author